Описание
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
An out-of-bounds write, and a use-after-free flaw was found in Ghostscript. The flaw is present in devices/vector/gdevtxtw.c, for txtwrite, due to a single character code in a PDF document that can map to more than one Unicode code point (for example, a ligature).
Отчет
The identified vulnerability in Ghostscript introduced in version 9.50 and FIxed in 9.53.0, this represents a important security issue due to its potential for exploitation by malicious actors. The out-of-bounds write and use-after-free flaws in the txtwrite module can be leveraged to execute arbitrary code or trigger denial-of-service attacks, compromising the integrity, confidentiality, and availability of systems where Ghostscript is deployed. Given the widespread use of Ghostscript in handling PDF documents across various platforms and applications, the vulnerability poses a significant risk to users' data and infrastructure. Red Hat Enterprise Linux is Not affected by this vulnerability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ghostscript | Not affected | ||
| Red Hat Enterprise Linux 7 | ghostscript | Not affected | ||
| Red Hat Enterprise Linux 8 | ghostscript | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:flatpak/ghostscript | Not affected | ||
| Red Hat Enterprise Linux 9 | ghostscript | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-a ...
EPSS
9.8 Critical
CVSS3